Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5r2m-hcrf-wwfq

Опубликовано: 29 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder.

Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder.

EPSS

Процентиль: 30%
0.00114
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 4.3
nvd
около 3 лет назад

Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files located in that folder.

EPSS

Процентиль: 30%
0.00114
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732